PT-2023-15530 · Secvisogram · Csaf-Validator-Service

·

CVE-2022-47925

·

Published

2023-03-27

·

Updated

2024-02-15

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Secvisogram csaf-validator-service versions prior to 0.1.0
Description The issue is related to insufficient input validation of requests by an unauthenticated remote user, which might lead to a partial Denial of Service (DoS) of the service. Specifically, the validate JSON endpoint processes tests with unexpected names. This affects only the request of the attacker.
Recommendations For versions prior to 0.1.0, update to version 0.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the validate JSON endpoint to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-47925

Affected Products

Csaf-Validator-Service